Executive brief
RTI Connext Professional is middleware that enables real-time data distribution and communication between networked applications. An off-by-one error in the core libraries allows attackers to write data out-of-bounds in memory, potentially causing application crashes, data corruption, or arbitrary code execution depending on memory layout and exploit conditions.
Technical details
An off-by-one error in RTI Connext Professional's core libraries permits out-of-bounds write operations, leading to buffer overflow. The vulnerability affects versions 7.0.0 before 7.3.1.6 and 7.4.0 before 7.7.0.1. Exploitation requires network access to a Connext endpoint but no authentication; patched versions are available.
Affected products
- RTI Connext Professional 7.0.0 before 7.3.1.6, 7.4.0 before 7.7.0.1
Timeline
- 2026-09-22: disclosed